mysql2@0.14.1 vulnerabilities

fast mysql driver. Implements core protocol, prepared statements, ssl and compression in native JS

Direct Vulnerabilities

Known vulnerabilities in the mysql2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Man in The Middle (MiTM)

mysql2 is a mostly API compatible with mysqljs and supports majority of features.

Affected versions of this package are vulnerable to Man in The Middle (MiTM). The package does not verify remote certificates and reject unauthorized SSL connections.

How to fix Man in The Middle (MiTM)?

Upgrade mysql2 to version 1.0.0-rc.1 or higher.